CVE-2024-34457

CVSS V2 None CVSS V3 None
Description
On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should upgrade to 2.1.4
Overview
  • CVE ID
  • CVE-2024-34457
  • Assigner
  • apache
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-07-22T09:48:23.130Z
  • Last Modified Date
  • 2024-07-22T17:57:24.474Z
History
Created Old Value New Value Data Type Notes
2024-07-23 13:17:51 Added to TrackCVE